XML 23 R8.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management, Strategy and Governance
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]

ITEM 1C. CYBERSECURITY.

 

Risk Management and Strategy

 

We recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures and processes that are designed to safeguard our information systems and to assess, identify and manage material risks from cybersecurity threats.

 

Managing Material Risks and Integrated Overall Risk Management

 

We have strategically integrated cybersecurity risk management into our broader risk management framework. This integration ensures that cybersecurity considerations are an integral part of our overall risk management system and processes. In addition, our risk management team works closely with our IT department to continuously evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.

 

Engaging Third Parties on Risk Management

 

Recognizing the complexity and evolving nature of cybersecurity threats, we engage a range of external experts, including cybersecurity assessors, consultants and auditors to evaluate and test our systems and to advise us on cybersecurity risk management processes. These relationships enable us to leverage specialized knowledge and insights, in an effort to keep our cybersecurity strategies and processes at the forefront of industry best practices. Our collaboration with these third parties includes regular audits, threat assessments and consultation on security enhancements.

 

Overseeing Third-party Risk

 

We have implemented processes to oversee and manage risks from cybersecurity threats associated with third-party service providers. We conduct security requirements assessments of third-party providers before engagement and maintain ongoing monitoring for compliance with our cybersecurity requirements. This approach is designed to mitigate risks related to data breaches or other security incidents originating from third parties.

 

Risks from Cybersecurity Threats

 

To date, we have not experienced any cybersecurity incidents that have materially affected our business strategy, results of operations or financial condition. However, we are subject to risks from cybersecurity threats that could have that effect, as further described in Part I, Item 1A "Risk Factors" of this Annual Report.

 

Governance

 

Our Board of Directors is acutely aware of the critical nature of managing risks associated with cybersecurity threats and has established robust processes to oversee such risks.

 

Board of Directors Oversight

 

The Audit Committee is central to the Board’s oversight of cybersecurity risks and has been delegated responsibility for assessing and managing such risks. The Audit Committee members have diverse expertise in risk management, technology and finance, equipping them to oversee cybersecurity risks effectively.

Management’s Role Managing Risk and Reporting to the Board of Directors

 

Our Chief Information Officer (“CIO”) and Chief Executive Officer (“CEO”) play a pivotal role in informing the Audit Committee on cybersecurity risks. They provide comprehensive briefings to the Audit Committee at their meetings on a regular basis. These briefings encompass a broad range of topics, including:

 

current cybersecurity landscape and emerging threats;
status of ongoing cybersecurity initiatives and strategies;
incident reports and learnings from any cybersecurity events; and
compliance with regulatory requirements and industry standards.

 

In addition to the scheduled meetings, the Audit Committee, CIO and CEO maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together, they receive updates on any significant developments in the cybersecurity domain. The Audit Committee actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives. This involvement ensures that cybersecurity considerations are integrated into our broader strategic objectives. In addition, the Audit Committee conducts an annual review of our cybersecurity posture and the effectiveness of our risk management strategies. This review helps in identifying areas for improvement and ensuring the alignment of cybersecurity efforts with the overall risk management framework.

 

Cybersecurity Risk Management Personnel

 

Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with our Director of IT Security, reporting to the CIO. Our Director of IT Security oversees our cybersecurity program, tests our compliance with standards, remediates known risks and leads our employee security training program. With over 25 years of experience in the field of cybersecurity, our Director of IT Security brings a wealth of expertise to the role, including extensive experience as an enterprise head of security and recognition within the industry. Our Director of IT Security provides in-depth knowledge and experience, which is instrumental in developing and executing our cybersecurity strategies.

 

Monitoring Cybersecurity Incidents

 

Our Director of IT Security implements and oversees processes for the regular monitoring of our information systems. This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities. In the event of a cybersecurity incident, we have in place a detailed incident response plan. This plan includes immediate actions designed to mitigate the impact and long-term strategies for remediation and prevention of future incidents. In addition, our Director of IT Security is continually informed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques. This ongoing knowledge acquisition assists in the prevention, detection, mitigation and remediation of cybersecurity incidents.

Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]

We have strategically integrated cybersecurity risk management into our broader risk management framework. This integration ensures that cybersecurity considerations are an integral part of our overall risk management system and processes. In addition, our risk management team works closely with our IT department to continuously evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.

Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]

Board of Directors Oversight

 

The Audit Committee is central to the Board’s oversight of cybersecurity risks and has been delegated responsibility for assessing and managing such risks. The Audit Committee members have diverse expertise in risk management, technology and finance, equipping them to oversee cybersecurity risks effectively.

Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Audit Committee is central to the Board’s oversight of cybersecurity risks and has been delegated responsibility for assessing and managing such risks. The Audit Committee members have diverse expertise in risk management, technology and finance, equipping them to oversee cybersecurity risks effectively
Cybersecurity Risk Role of Management [Text Block]

Management’s Role Managing Risk and Reporting to the Board of Directors

 

Our Chief Information Officer (“CIO”) and Chief Executive Officer (“CEO”) play a pivotal role in informing the Audit Committee on cybersecurity risks. They provide comprehensive briefings to the Audit Committee at their meetings on a regular basis. These briefings encompass a broad range of topics, including:

 

current cybersecurity landscape and emerging threats;
status of ongoing cybersecurity initiatives and strategies;
incident reports and learnings from any cybersecurity events; and
compliance with regulatory requirements and industry standards.

 

In addition to the scheduled meetings, the Audit Committee, CIO and CEO maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together, they receive updates on any significant developments in the cybersecurity domain. The Audit Committee actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives. This involvement ensures that cybersecurity considerations are integrated into our broader strategic objectives. In addition, the Audit Committee conducts an annual review of our cybersecurity posture and the effectiveness of our risk management strategies. This review helps in identifying areas for improvement and ensuring the alignment of cybersecurity efforts with the overall risk management framework.

Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] the Audit Committee, CIO and CEO maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together, they receive updates on any significant developments in the cybersecurity domain. The Audit Committee actively participates in strategic decisions related to cybersecurity, offering guidance and approval for major initiatives.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]

Cybersecurity Risk Management Personnel

 

Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with our Director of IT Security, reporting to the CIO. Our Director of IT Security oversees our cybersecurity program, tests our compliance with standards, remediates known risks and leads our employee security training program. With over 25 years of experience in the field of cybersecurity, our Director of IT Security brings a wealth of expertise to the role, including extensive experience as an enterprise head of security and recognition within the industry. Our Director of IT Security provides in-depth knowledge and experience, which is instrumental in developing and executing our cybersecurity strategies.

Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]

Monitoring Cybersecurity Incidents

 

Our Director of IT Security implements and oversees processes for the regular monitoring of our information systems. This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities. In the event of a cybersecurity incident, we have in place a detailed incident response plan. This plan includes immediate actions designed to mitigate the impact and long-term strategies for remediation and prevention of future incidents. In addition, our Director of IT Security is continually informed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true